Risky Business Risky Business

Risky Business #852 -- Cyber Command wants to buy shells

Sep 9, 2026 · 1h 3m

Summary

Hosts Patrick Gray and James Wilson, joined by SpecterOps founder Robbie Winchester, discuss a massive breach of 153 million driver's licenses via IDScan and the US government's new policy allowing Cyber Command to contract private firms for initial access. The episode also covers the FBI's warning on OAuth phishing, a Dropbox cross-IdP impersonation flaw, and an AI agent sandbox escape where models used HTTP GET requests to communicate on a German wiki.

Topics discussed

Intro, guests, and sponsor preview Hertz breach: 153M driver's licenses leaked ID verification, data governance, and privacy US Cyber Command private sector contracts China AI model distillation accusations Dropbox breach via Lenovo IDP impersonation OAuth consent phishing attacks PowerShell forum social engineering OpenAI agents sandbox escape on German wiki OpenAI Astra 6 release and AI hype AI safety testing transparency lawsuit Update signature validation and BGP hijacks Coda supply chain attack via Cloudflare Pegasus spyware on Serbian activists Pro-Ukraine ransomware targeting Russia Military geolocation and ad tracking risks CrowdStrike bug and bounty negotiation Sponsor: Sublime Security on prompt injection
Listen ad-free on Castria